Summary & highlights
FTP Server Banners Abused as Dead-Drop Resolvers to Deliver E4del and PINHOLE Windows RATs. Sophos X-Ops: Attackers Impersonate Claude, ChatGPT, Copilot and Perplexity to Distribute Infostealers, Backdoors and Malicious Browser Extensions. 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi).
Highlights
- TL-2026-2119 — FTP Server Banners Abused as Dead-Drop Resolvers to Deliver E4del and PINHOLE Windows RATs
- TL-2026-2120 — Sophos X-Ops: Attackers Impersonate Claude, ChatGPT, Copilot and Perplexity to Distribute Infostealers, Backdoors and Malicious Browser Extensions
- TL-2026-2125 — 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)
- TL-2026-2126 — Illegal IPL Betting Platform Network: 1,200+ Domains, Deepfake Celebrity Endorsements, and Systematic Withdrawal Blocking (CloudSEK 'Hit Wicket' Report)
- TL-2026-2121 — Critical Type Confusion in isolated-vm (GHSA-864f-rcv7-6rh4) Enables Sandbox Escape and RCE on Host
Theme of the day
Supply-chain compromise and critical RCEs dominated the day, with Spring and Microsoft Entra ID flaws enabling pre-install attacks, while AI-augmented adversaries and ransomware wiper behavior expanded the threat surface.
- c2-infrastructure
- credential-theft
- privilege-escalation
- remote-code-execution
- authentication-bypass
Threats published
16 threat lines in the 2026-08-23 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Critical Type Confusion in isolated-vm (GHSA-864f-rcv7-6rh4) Enables Sandbox Escape and RCE on HostCRITICAL
- FamousSparrow APT Targets Azerbaijani Oil & Gas Sector via ProxyShell/ProxyNotShell Exchange ExploitationCRITICAL
- Axios npm Supply Chain Compromise by Sapphire Sleet (DPRK) — Cross-Platform RAT via Phantom Dependency (update)CRITICAL
- CVE-2026-33824: Windows IKE Extensions Unauthenticated RCE via Double Free (update)CRITICAL
- Sorry Ransomware Mass Exploitation of cPanel/WHM Authentication Bypass CVE-2026-41940 (44,000+ Servers Compromised) (update)CRITICAL
- Critical GitLab GraphQL Flaw (CVE-2026-19478, CVSS 9.4) Could Let Unauthenticated Attackers Delete Public Projects (update)CRITICAL
- CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with Accompanying CVE-2026-19489 Memory Overflow (CVSS 8.8) (update)CRITICAL
- NASA JPL AIT-GUI Missing Authentication and CSRF Flaw Allows Unauthenticated Spacecraft Command Injection (CVE-2026-60112, CVSS 9.8/9.4) (update)CRITICAL
- CISA KEV: Active Exploitation of TrueConf Server Vulnerabilities (CVE-2026-72529, CVE-2026-72530) by Head Mare APT (update)CRITICAL
- FTP Server Banners Abused as Dead-Drop Resolvers to Deliver E4del and PINHOLE Windows RATsHIGH
- Sophos X-Ops: Attackers Impersonate Claude, ChatGPT, Copilot and Perplexity to Distribute Infostealers, Backdoors and Malicious Browser ExtensionsHIGH
- 2026 Ransomware Surge Targeting US Organizations: Identity-First Compromise, BYOVD, and Living-Off-the-Cloud Exfiltration (Qilin, Akira, Clop, INC Ransom, Play, DragonForce, Sinobi)HIGH
- Illegal IPL Betting Platform Network: 1,200+ Domains, Deepfake Celebrity Endorsements, and Systematic Withdrawal Blocking (CloudSEK 'Hit Wicket' Report)HIGH
- Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet (update)HIGH
- JarService/Zhima Multi-Stage Android Malware Targets DoFun Automotive Head Units, Linked to BADBOX Botnet (update)HIGH
- Banking Trojans: Manic, Grandoreiro, and ToxicPanda 2.0 in the Spotlight (update)HIGH
Techniques observed
197 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- AML.T0051
- T0836
- T0853
- T0855
- T0863
- T0871
- T0883
- T1003
- T1003.001
- T1005
- T1014
- T1016
- T1020
- T1021
- T1021.001
- T1021.002
- T1027
- T1027.002
- T1033
- T1036
- T1036.005
- T1041
- T1046
- T1053
- T1053.003
- T1053.005
- T1055
- T1055.004
- T1055.012
- T1056.001
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1068
- T1070
- T1070.002
- T1070.004
- T1071
- T1071.001
- T1074
- T1078
- T1078.003
- T1082
- T1083
- T1087
- T1090
- T1090.002
- T1095
- T1098
- T1098.004
- T1102
- T1102.001
- T1102.002
- T1105
- T1106
- T1112
- T1113
- T1115
- T1125
- T1132.001
- T1133
- T1136
- T1136.001
- T1140
- T1176
- T1189
- T1190
- T1195
- T1195.001
- T1195.002
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.004
- T1210
- T1211
- T1213
- T1213.003
- T1218.005
- T1219
- T1404
- T1406
- T1407
- T1414
- T1417.001
- T1417.002
- T1421
- T1422
- T1426
- T1430
- T1437
- T1437.001
- T1474
- T1481
- T1485
- T1486
- T1489
- T1490
- T1491
- T1496
- T1496.002
- T1497.001
- T1499
- T1499.004
- T1505
- T1505.003
- T1512
- T1518
- T1518.001
- T1528
- T1529
- T1531
- T1533
- T1539
- T1543
- T1543.003
- T1546
- T1546.015
- T1547
- T1547.001
- T1550
- T1552
- T1552.001
- T1553
- T1553.002
- T1554
- T1555
- T1555.003
- T1556
- T1560
- T1562.001
- T1564.001
- T1565
- T1565.001
- T1565.002
- T1566
- T1566.001
- T1566.002
- T1567
- T1569
- T1569.002
- T1571
- T1572
- T1574
- T1574.001
- T1577
- T1583
- T1583.001
- T1583.006
- T1583.008
- T1584
- T1584.004
- T1585
- T1585.001
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.002
- T1588.005
- T1588.006
- T1588.007
- T1589
- T1590
- T1590.005
- T1592.002
- T1595
- T1595.002
- T1596.005
- T1603
- T1604
- T1606
- T1606.001
- T1608.001
- T1608.006
- T1611
- T1620
- T1623
- T1624.001
- T1626.001
- T1636.002
- T1636.003
- T1636.004
- T1639
- T1643
- T1650
- T1657
- T1660
- T1684.001
- T1685
Threat actors
6 named threat actors across the reports.
- Salt Typhoon - G1045
- MoYu Group
- APT38
- knaithe (aka KnYuan)
- Mr_Rot13
- Head Mare
Nation-state attribution
- China
- North Korea
- Ukraine
Threat categories
- MALWARE
- RANSOMWARE
- THREAT_INTEL
- VULNERABILITY
- APT
- SUPPLY_CHAIN
Severity breakdown
- critical9
- high7
- medium0
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 132
- file 128
- behavioral 90
- tool 38
- infrastructure 34
- malware 30
- package 30
- entity 28
- technique 2
- host 1